Skip to content

article

Rotating and Retiring Credentials

Generate a prioritized rotation plan, change credentials in the right order, and retire the ones you no longer need.

Credentials don't stay safe forever. Passwords age, keys get exposed, and staff leave. Rotation is the practice of changing credentials regularly and immediately after any exposure. StretchVault turns that from guesswork into a prioritized plan.

Why rotate

Even a strong password becomes a liability over time: the longer it exists, the more places it may have been typed, screenshotted, or leaked. Rotating on a schedule limits how long any single leaked value is useful, and rotating right after exposure shuts an attacker out fast. StretchVault's rotation planning tells you which credentials to change and in what order, so you spend effort where it matters most.

Generating a rotation plan

  1. Open the Watchtower/rotation area for the vault you want to plan.
  2. Choose Rotation plan.
  3. StretchVault reviews the vault and returns a prioritized list of items to rotate, each with the reasons it was included.

Every item on the plan is assigned a priority:

  • Critical — the secret is exposed (found in a breach or flagged). Rotate these first, today.
  • High — the secret is reused across items, or is weak (below the strength threshold).
  • Medium — the secret is old, beyond the maximum age (365 days by default).
  • Low — minor issues worth addressing when convenient.

The plan is sorted so the most urgent items are at the top, and it summarizes how many fall into each priority. Running the full plan saves it to your Audit history; a read-only preview computes the same list without recording it.

Rotating an item, step by step

  1. Open the top item on the plan.
  2. Open the Generator and create a fresh, strong value (see Generating Strong Passwords and Passphrases).
  3. Change the credential in the real system first (the website, server, or service).
  4. Return to StretchVault, edit the item, paste the new secret, and save. Saving a new value updates the item's rotation date and re-analyzes its strength.
  5. Move to the next item and repeat, working top-down by priority.
  6. Re-run Watchtower to confirm the score improved.

Always change the credential in the external system before saving it in StretchVault, so the vault always reflects the value that actually works.

A realistic example

Meridian Studio generates a rotation plan for their Infrastructure vault. The plan lists a critical item (a database password that appeared in a breach list), two high items (an API key reused between staging and production, and a weak SFTP password), and one medium item (a server login untouched for 14 months). The engineer rotates them in that exact order: fixes the exposed database password immediately, splits the reused API key into two unique keys, strengthens the SFTP password, and finally refreshes the aging server login. A re-run of Watchtower moves the vault from fair to excellent, and the saved run documents the work.

Retiring credentials you no longer need

Rotation keeps active credentials safe; retiring removes ones you don't need at all — the cleanest way to reduce risk is to have fewer secrets. To retire an item:

  1. Confirm the credential is genuinely no longer used (and, where applicable, deactivate it in the external system).
  2. Open the item and choose Delete.
  3. The item is removed from your vault and lists.

Before a client offboards or a project ends, sweep the vault (a retire-soon tag helps) and delete every credential that no longer has a purpose.

Tips

  • Always work the plan top-down: exposed first, then reused/weak, then old.
  • Change the external system first, then save the new value in StretchVault — never the reverse.
  • Rotate to a freshly generated value, not a small edit of the old one; near-duplicates are still guessable.
  • Pair rotation with revoking grants for anyone who shouldn't retain access to the new secret.
  • Set a recurring reminder (monthly or quarterly) to generate a fresh plan so nothing quietly ages past policy.

Troubleshooting

"StretchVault engine is not enabled." Rotation planning needs the security engine. Check the Health tab and contact your administrator if it's offline.

An item I rotated still shows as old. Age is tracked from the last saved secret change. Make sure you actually saved a new secret value on the item (leaving the secret field blank keeps the old one and its date).

I deleted the wrong item. Deletion removes the item from your lists. Re-create it if needed, and rotate the underlying credential to be safe.

FAQ

How often should I rotate? At minimum, rotate anything the plan marks exposed immediately, and review the plan quarterly. High-value infrastructure and API keys deserve a tighter cadence.

Does StretchVault change the password on the website for me? No. StretchVault plans and records rotation and stores the new value; you change the credential in the external system, then save it here.

Was this helpful?

Help us improve this article

Use these controls to share whether this answer solved the issue. Feedback helps prioritize updates to StretchSuite Support.